skip to content
emilloc
esc
back
tags
apache-arrow
CVE
25087
signed overflow in arrow's ipc reader
28 feb 2026
· CVE-2026-25087 · cve, fuzzing, apache-arrow, c++ · 3 min
the "prebuffered" read path had zero fuzz coverage, and the
CoalesceReadRanges()
function didn't check whether offset + length overflows int64. fixed in PR #48925.